frame-busting-bypass

1 article
sort: new top best
clear filter
0 6/10

Security researcher discovered and bypassed a clickjacking vulnerability on Binary.com's ticktrade subdomain by exploiting HTML5 sandboxed iframes with specific permissions (allow-modals, allow-scripts, allow-forms, allow-popups, allow-same-origin) to circumvent JavaScript frame-busting defenses.

Binary.com Binary Ltd. ticktrade.binary.com Ameer Assadi
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details